City of Middletown reported to HHS on 2026-06-03 a Hacking/IT Incident affecting 20608 individuals. Breached information located on Network Server.
Affected (this filing): 20,608
Clustered 3 filings across 3 jurisdictions · filing window Jun 3, 2026 → Jun 8, 2026. View entity profile → Other incidents for this victim →
incident inc_5dc93077b4f44b76 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Time between earliest and latest filing
Not recorded for this incident
Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
Identity (basic) · Government ID
IN NH OH
HHS OCR · State AG
Earliest sighting first · deep chronology in Litigation Timeline
Jul 29, 2025
When the intrusion reportedly occurred, per the linked filings
May 18, 2026
Reported by NEW HAMPSHIRE AG filing
City of Middletown reported to HHS on 2026-06-03 a Hacking/IT Incident affecting 20608 individuals. Breached information located on Network Server.
Affected (this filing): 20,608
City of Middletown reported a data breach to the Indiana Attorney General. The breach occurred on 2025-07-29 and was reported on 2026-06-03. 140 Indiana residents were affected. 123,791 individuals affected in total.
Affected (this filing): 123,791
City of Middletown, Ohio, notified the New Hampshire Attorney General's Office of an unauthorized network access incident affecting approximately 3 residents. The breach occurred between July 29, 2025, and August 17, 2025, and was discovered on May 18, 2026. Compromised data included full names, Social Security numbers, and driver's license/state ID numbers. The City engaged external cybersecurity professionals, notified affected residents, and provided complimentary credit monitoring services.
Affected (this filing): 3
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.